@hasna/sandboxes
Universal cloud sandbox manager for AI coding agents - supports e2b, Daytona, Modal
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publish tooling variance, no behavioral signal; unchanged provenance direction overall. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): pg is a mainstream, well-known DB driver fitting the package's storage feature. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Fast iterative releases, no accompanying malicious behavior found. | ai | |
| phantom-deps | phantom-dep:@hasna/events | AI (phantom-deps): Same org scope; likely used indirectly via @hasna/cloud or similar internal dep. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is declared as a runtime dep and referenced in config; phantom-dep heuristic fires due to indirect/config-only usage. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Creates only a local config directory; no network calls or code execution. | ai | |
| phantom-deps | phantom-dep:@hasna/cloud | AI (phantom-deps): Same-org package; phantom-dep heuristic unreliable for scoped sibling packages. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Marked external in build script; declared but not directly imported by design. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Marked external in build script; declared but not directly imported by design. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Declared dep used via config/type references; consistent with build externals pattern. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Marked external in build script; declared but not directly imported by design. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 1.1.0 | 6 / 2 | |
| 1.0.3 | 6 / 2 | |
| 1.0.2 | 5 / 2 | |
| 1.0.1 | 5 / 2 | |
| 1.0.0 | 5 / 2 | |
| 0.1.43 | 12 / 4 | |
| 0.1.42 | 11 / 4 | |
| 0.1.41 | 11 / 4 | |
| 0.1.39 | 11 / 3 | |
| 0.1.37 | 11 / 3 | |
| 0.1.32 | 10 / 3 | |
| 0.1.31 | 10 / 3 | |
| 0.1.30 | 9 / 4 | |
| 0.1.29 | 9 / 4 | |
| 0.1.28 | 9 / 3 | |
| 0.1.27 | 9 / 3 | |
| 0.1.26 | 9 / 3 | |
| 0.1.25 | 9 / 3 | |
| 0.1.24 | 9 / 3 | |
| 0.1.23 | 9 / 3 | |
| 0.1.22 | 9 / 3 | |
| 0.1.21 | 9 / 3 | |
| 0.1.20 | 9 / 3 | |
| 0.1.19 | 9 / 3 | |
| 0.1.18 | 9 / 3 | |
| 0.1.17 | 8 / 3 | |
| 0.1.16 | 8 / 3 | |
| 0.1.15 | 8 / 3 | |
| 0.1.14 | 8 / 3 | |
| 0.1.13 | 8 / 3 | |
| 0.1.12 | 8 / 3 | |
| 0.1.11 | 8 / 3 | |
| 0.1.10 | 8 / 3 | |
| 0.1.9 | 9 / 3 | |
| 0.1.8 | 9 / 3 | |
| 0.1.7 | 9 / 3 | |
| 0.1.6 | 9 / 3 | |
| 0.1.5 | 8 / 3 | |
| 0.1.3 | 8 / 3 | |
| 0.1.2 | 8 / 3 | |
| 0.1.1 | 8 / 3 | |
| 0.1.0 | 9 / 3 |
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.43
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.